Earlier quoted context omitted.
It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..
I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)
CISA Alert: Water Sector PLC Targeting
51–60 of 78 posts
Re: CISA Alert: Water Sector PLC Targeting
#52Earlier quoted context omitted.
Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.
“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.
Re: CISA Alert: Water Sector PLC Targeting
#53> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Describe the network security of the industrial automation industry and their customers in a single statement. Lol.
It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..
Re: CISA Alert: Water Sector PLC Targeting
#54Re: CISA Alert: Water Sector PLC Targeting
#55Earlier quoted context omitted.
I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)
Dial up into an air gapped network defeats the purpose of being air gapped. I would think the bare minimum standard is that there is no way to change anything in the control systems without being physically present at the facility, past it's physical security boundary.
Re: CISA Alert: Water Sector PLC Targeting
#56Earlier quoted context omitted.
So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota? > failed to anticipate not only these infrastructure breach They've been warning them for close to two decades. Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.
The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.
Re: CISA Alert: Water Sector PLC Targeting
#57Earlier quoted context omitted.
The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.
There's no "national infrastructure" for water. Aside from what the EPA does, it isn't within the remit of the federal government to manage municipality water systems.
Re: CISA Alert: Water Sector PLC Targeting
#58Earlier quoted context omitted.
“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.
Not really. Just patch and reboot. Pretty simple.
Re: CISA Alert: Water Sector PLC Targeting
#59Earlier quoted context omitted.
It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports. > make the feds do it National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a w…
National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground? NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so. I agree that in theory this would not be a…
I'll say, you should see the hours I have to work sometimes. Honestly I've rarely seen IT jobs pay OT.
Re: CISA Alert: Water Sector PLC Targeting
#60> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Describe the network security of the industrial automation industry and their customers in a single statement. Lol.